Hi Mark,
while our legal team reviewed the Vulnerability Group proposal, they
complained that the term "rough consensus" is never defined, neither
in the Vulnerability Group proposal nor in the OpenJDK Bylaws.
Would it be possible to rephrase "rough consensus" as "lazy consensus"
which is defined in the Bylaws? I understand that in the Bylaws, "lazy
consensus" is defined with respect to voting and we don't want to have
a vote for every decision but on the other hand, the definition of
"lazy consensus" as "not having any veto" seems appropriate to me in
the context where "rough consensus" is currently being used in the
Vulnerability Group proposal.
If that's is not possible, the Vulnerability Group proposal should
define in more detail what it means by "rough consensus".
Thank you and best regards,
Volker
On Mon, Oct 16, 2017 at 4:10 PM, <mark.reinhold at oracle.com> wrote:
> 2017/10/13 11:03:20 -0700, ysr1729 at gmail.com:
>> What's the process & timeframe for obtaining membership to the group
>> (presumably after the revised version of the document is out?).
>>http://cr.openjdk.java.net/~mr/ojvg/#membership>> - Mark